PULSE NAME
Donuts and Beagles: Fake Claude site spreads backdoor
WHITE AlienVault 2026-05-07 Modified: 2026-05-08
2
IOCs
LOW VOLUME
A fraudulent website impersonating Anthropic's Claude AI platform has been distributing a previously undocumented backdoor called Beagle through malvertising campaigns. The attack begins when victims download a fictitious tool named Claude-Pro Relay from claude-pro[.]com, delivered as a 505 MB ZIP archive. The infection chain utilizes DLL sideloading, exploiting a signed G DATA antivirus updater to load malicious code. The technique mirrors PlugX delivery methods but deploys different payloads. Beagle supports eight commands including shell execution, file transfer, and directory listing, communicating with C2 servers using AES encryption. Related samples dating to February 2026 have been identified, with some variants delivering AdaptixC2 framework. Additional domains impersonated security vendors like Trellix, CrowdStrike, and SentinelOne. The infrastructure spans Cloudflare for distribution and Alibaba Cloud for command and control.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Beagle DonutLoader AdaptixC2 PlugX - S0013 Thoper TVT DestroyRAT Sogu Kaba Korplug
Indicators of Compromise (2)
All domain hostname
TYPEINDICATORDESCRIPTIONCREATED
domain claude-pro.com 2026-05-07
hostname license.claude-pro.com 2026-05-07